{"id":92462,"url":"https://github.com/cybersecurity-dev/awesome-malware-reverse-engineering-certification","name":"awesome-malware-reverse-engineering-certification","description":"Awesome Malware Reverse Engineering Certification","projects_count":53,"last_synced_at":"2026-09-23T01:00:56.009Z","repository":{"id":305584497,"uuid":"1023272200","full_name":"cybersecurity-dev/awesome-malware-reverse-engineering-certification","owner":"cybersecurity-dev","description":"Awesome Malware Reverse Engineering Certification","archived":false,"fork":false,"pushed_at":"2026-07-12T15:52:42.000Z","size":83,"stargazers_count":2,"open_issues_count":0,"forks_count":0,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-07-26T02:04:02.297Z","etag":null,"topics":["certification","giac-certification","grem","grem-certification","malware-certification","malware-research","reverse-engineering","reverse-engineering-certification"],"latest_commit_sha":null,"homepage":"https://cyberthreatdefence.com/","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"cc0-1.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/cybersecurity-dev.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2025-07-20T22:18:23.000Z","updated_at":"2026-07-12T15:52:46.000Z","dependencies_parsed_at":"2026-05-17T03:01:33.271Z","dependency_job_id":null,"html_url":"https://github.com/cybersecurity-dev/awesome-malware-reverse-engineering-certification","commit_stats":null,"previous_names":["cybersecurity-dev/awesome-malware-reverse-engineering-certification"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/cybersecurity-dev/awesome-malware-reverse-engineering-certification","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cybersecurity-dev%2Fawesome-malware-reverse-engineering-certification","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cybersecurity-dev%2Fawesome-malware-reverse-engineering-certification/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cybersecurity-dev%2Fawesome-malware-reverse-engineering-certification/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cybersecurity-dev%2Fawesome-malware-reverse-engineering-certification/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/cybersecurity-dev","download_url":"https://codeload.github.com/cybersecurity-dev/awesome-malware-reverse-engineering-certification/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/cybersecurity-dev%2Fawesome-malware-reverse-engineering-certification/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":36643789,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-08-06T04:43:03.162Z","status":"online","status_checked_at":"2026-08-14T02:00:06.934Z","response_time":54,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"created_at":"2025-08-05T22:56:13.792Z","updated_at":"2026-09-23T01:00:56.009Z","primary_language":null,"list_of_lists":false,"displayable":true,"categories":["Resources","[GIAC Reverse Engineering Malware Certification (GREM)](https://www.giac.org/certifications/reverse-engineering-malware-grem/) [![Reddit](https://img.shields.io/badge/Reddit-FF4500?logo=reddit\u0026logoColor=white)](https://www.reddit.com/r/GIAC/)","Videos","Certifications"],"sub_categories":["Malware Research Company","Malware Researcher Hired Companies","My Other Awesome Lists","Courses","License","GitHub Repositories \\\u0026 Awesome Lists","Videos"],"readme":"\u003cdiv align=\"center\"\u003e\n\n```mermaid\nflowchart LR\n\n    A[Security+] --\u003e B[CySA+]\n\n    B --\u003e C{Specialization}\n\n%% Malware Analysis Track\n    C --\u003e D[Malware Analysis]\n\n    D --\u003e D0[PMAT]\n    D0 --\u003e D1[PMRP]\n    D1 --\u003e D2[CMA]\n    D2 --\u003e D3[GREM]\n    D3 --\u003e D4[FOR610]\n\n%% Reverse Engineering Track\n    C --\u003e E[Reverse Engineering]\n\n    E --\u003e E1[MRE]\n    E1 --\u003e E2[GREM]\n    E2 --\u003e E3[FOR610]\n    E3 --\u003e E4[FOR710]\n\n%% DFIR Track\n    C --\u003e F[DFIR]\n\n    F --\u003e F1[GCFE]\n    F1 --\u003e F2[GCFA]\n    F2 --\u003e F3[FOR500]\n\n%% Career Outcomes\n    D4 --\u003e G[Senior Malware Analyst]\n    E4 --\u003e H[Senior Reverse Engineer]\n    F3 --\u003e I[DFIR Lead]\n\n    G --\u003e J[Malware Researcher]\n    H --\u003e J\n    I --\u003e J\n\n    J --\u003e K[Threat Intelligence Expert]\n    style C fill:#990000,stroke:#660000,color:#ffffff\n    style D fill:#0b5394,stroke:#073763,color:#ffffff\n    style E fill:#f1c232,stroke:#bf9000,color:#ffffff\n    style J fill:#0b5394,stroke:#073763,color:#ffffff\n    style K fill:#674ea7,stroke:#351c75,color:#ffffff\n```\n\n# **`Awesome`** [Malware](https://wikipedia.org/wiki/Malware_analysis) \u0026 [Reverse Engineering](https://www.sei.cmu.edu/reverse-engineering-for-malware-analysis/) Certification [![Awesome](https://awesome.re/badge.svg)](https://awesome.re)\n\u003c/div\u003e\n\n[![YouTube](https://img.shields.io/badge/YouTube-%23FF0000.svg?style=for-the-badge\u0026logo=YouTube\u0026logoColor=white)](https://youtube.com/playlist?list=PL9V4Zu3RroiX6hut9Ecr0rjgzXXf8gN8q\u0026si=HMSqZT9imQjBFkPY) [![Reddit](https://img.shields.io/badge/Reddit-FF4500?style=for-the-badge\u0026logo=reddit\u0026logoColor=white)](https://www.reddit.com/r/SecurityCareerAdvice/new/)\n\n\u003cp align=\"center\"\u003e\n    \u003ca href=\"https://github.com/cybersecurity-dev/\"\u003e\u003cimg height=\"25\" src=\"https://github.com/cybersecurity-dev/cybersecurity-dev/blob/main/assets/github.svg\" alt=\"GitHub\"\u003e\u003c/a\u003e\n    \u0026nbsp;\n    \u003ca href=\"https://www.youtube.com/@CyberThreatDefense\"\u003e\u003cimg height=\"25\" src=\"https://github.com/cybersecurity-dev/cybersecurity-dev/blob/main/assets/youtube.svg\" alt=\"YouTube\"\u003e\u003c/a\u003e\n    \u0026nbsp;\n    \u003ca href=\"https://cyberthreatdefence.com/my_awesome_lists\"\u003e\u003cimg height=\"20\" src=\"https://github.com/cybersecurity-dev/cybersecurity-dev/blob/main/assets/blog.svg\" alt=\"My Awesome Lists\"\u003e\u003c/a\u003e\n\u003c/p\u003e\n\n## 📖 Contents\n- [Certifications](#certifications)\n- [GIAC Reverse Engineering Malware Certification (GREM)](#giac-reverse-engineering-malware-certification-grem-)\n- [Resources](#resources)\n    - [Videos](#videos)\n    - [Courses](#courses)\n    - [GitHub Repositories \\\u0026 Awesome Lists ](#github-repositories--awesome-lists)\n    - [Malware Research Company](#malware-researcher-hired-companies)\n- [My Other Awesome Lists](#my-other-awesome-lists)\n- [Contributing](#contributing)\n- [Contributors](#contributors)\n\n## Certifications\n- [GIAC Reverse Engineering Malware Certification (**`GREM`**)](https://www.giac.org/certifications/reverse-engineering-malware-grem)\n- [Practical Malware Research Professional (**`PMRP`**)](https://certifications.tcm-sec.com/pmrp/)\n- [MCSI Certified Reverse Engineer (**`MRE`**)](https://www.mosse-institute.com/certifications/mre-certified-reverse-engineer.html)\n- [Certified Malware Analysis (**`CMA`**)](https://www.ncsi.institute/collections/board-certifications-online-career-development/products/certified-malware-analysis)\n\n\n## [GIAC Reverse Engineering Malware Certification (GREM)](https://www.giac.org/certifications/reverse-engineering-malware-grem/) [![Reddit](https://img.shields.io/badge/Reddit-FF4500?logo=reddit\u0026logoColor=white)](https://www.reddit.com/r/GIAC/new/)\n* **Analyzing Malicious Office Macros:** The candidate will be able to analyze macros and scripts embedded in suspicious Microsoft Office files to understand their capabilities.\n* **Analyzing Malicious PDFs:** The candidate will be able to analyze suspicious PDFs and embedded scripts to understand the nature of the threat they might pose.\n* **Analyzing Malicious RTF Files:** The candidate will be able to analyze suspicious RTF files and embedded shellcode to understand their capabilities.\n* **Analyzing Obfuscated Malware:** The candidate will be able to identify packed Windows executables and obfuscated malicious JavaScript and unpack it to gain visibility of it's key capabilities.\n* **Behavioral Analysis Fundamentals:** The candidate will be able analyze static properties of a suspected malware sample, develop theories regarding its nature, and determine subsequent analysis steps.\n* **Common Malware Patterns:** The candidate will be able to identify common API calls used by malware and understand what capabilities the APIs offer to the malware samples. The candidate will be able to identify common techniques used by malware including code injection, hooking, and process hollowing techniques.\n* **Core Reverse Engineering Concepts:** The candidate will apply dynamic analysis techniques to examine a malware sample in a debugger and will apply static analysis techniques to interpret common assembly instructions and patterns in Windows malware using a disassembler.\n* **Examining .NET Malware:** The candidate will be able to analyze .NET programs to understand their capabilities.\n* **Identifying and Bypassing Anti-Analysis Techniques:** The candidate will be able to identify and bypass common debugger detection and data protection measures used in malware, including the detection of security tools.\n* **Malware Analysis Fundamentals:** The candidate will be able to describe key methods for analyzing malicious software and identify the needs of malware analysis lab.\n* **Malware Flow Control and Structures:** The candidate will be able to analyze common execution flow control mechanisms, such as loops and conditional statements, in assembly language.\n* **Overcoming Misdirection Techniques:** The candidate will be able to overcome misdirecting execution workflow as an anti-analysis technique used in malware.\n* **Reversing Functions in Assembly:** The candidate will be able to analyze malware functions in assembly language to understand use of parameters, return values and other structural elements.\n* **Static Analysis Fundamentals:** The candidate will be able analyze static properties of a suspected malware sample, develop theories regarding its nature, and determine subsequent analysis steps.\n* **Unpacking and Debugging Packed Malware:** The candidate will demonstrate process for unpacking malware using a debugger and repairing unpacked malware for further analysis.\n\n## Resources\n\n```mermaid\nflowchart LR\n\n    A[Programming] --\u003e B[Assembly]\n    B --\u003e C[Reverse Engineering]\n\n    C --\u003e C1[Ghidra]\n    C --\u003e C2[IDA Pro]\n    C --\u003e C3[x64dbg]\n    C --\u003e C4[Binary Ninja]\n    C --\u003e C5[Radare2]\n\n    C --\u003e D[Malware Analysis]\n\n    D --\u003e D1[Static Analysis]\n    D --\u003e D2[Dynamic Analysis]\n    D --\u003e D3[Memory Analysis]\n    D --\u003e D4[Network Analysis]\n\n    D --\u003e E[Advanced Malware Research]\n\n    E --\u003e E1[Packer Analysis]\n    E --\u003e E2[Anti Analysis]\n    E --\u003e E3[Rootkits]\n    E --\u003e E4[Kernel Malware]\n\n    E --\u003e F[Certifications]\n\n    F --\u003e F1[TCM PMAT]\n    F --\u003e F2[GREM]\n    F --\u003e F3[FOR610]\n    F --\u003e F4[OSEP]\n    F --\u003e F5[OSCE3]\n\n    F --\u003e G[Senior Malware Researcher]\n\n    style C fill:#990000,stroke:#660000,color:#ffffff\n    style D fill:#0b5394,stroke:#073763,color:#ffffff\n    style E fill:#674ea7,stroke:#351c75,color:#ffffff\n    style F fill:#f1c232,stroke:#bf9000,color:#ffffff\n\n```\n\n### Videos\n* [GIAC GSEC Exam by @PicanteNino](https://youtu.be/uKCvN658HnU?si=dSzDFtyBReMQyGZ_)\n\n### Courses\n* [FOR610: Reverse-Engineering Malware: Malware Analysis Tools and Techniques by SANS](https://www.sans.org/cyber-security-courses/reverse-engineering-malware-malware-analysis-tools-techniques)\n* [FOR710: Reverse-Engineering Malware: Advanced Code Analysis by SANS](https://www.sans.org/cyber-security-courses/reverse-engineering-malware-advanced-code-analysis)\n\n### GitHub Repositories \\\u0026 Awesome Lists \n* You can access the `Linux based static malware analysis` steps using the following link: [Analysis Steps Link](https://github.com/cybersecurity-dev/awesome-static-linux-malware-analysis)\n    * For additional resources and reference materials using the following link: [Resource Link](https://github.com/cybersecurity-dev/awesome-linux-malware-analysis-resources)\n* You can access the `Windows based static malware analysis` steps using the following link: [Analysis Steps Link](https://github.com/cybersecurity-dev/awesome-static-windows-malware-analysis)\n    * For additional resources and reference materials using the following link: [Resource Link](https://github.com/cybersecurity-dev/awesome-windows-malware-analysis-resources)\n* You can access the `Android based static malware analysis` steps using the following link: [Analysis Steps Link](https://github.com/cybersecurity-dev/awesome-static-windows-malware-analysis)\n    * For additional resources and reference materials using the following link: [Resource Link](https://github.com/cybersecurity-dev/awesome-windows-malware-analysis-resources)\n\n### Malware Researcher Hired Companies\n- [Acronis](https://www.acronis.com/) - [_Jobs_](https://www.acronis.com/en-us/careers/jobs/)\n- [Akamai](https://www.akamai.com/) - [_Jobs_](https://jobs.akamai.com/)\n- [Anomali](https://www.anomali.com/) - [_Jobs_](https://jobs.lever.co/anomali/)\n- [BAE Systems](https://www.baesystems.com/) - [_Jobs_](https://jobsearch.baesystems.com/)\n- [Check Point Software](https://www.checkpoint.com/) - [_Jobs_](https://careers.checkpoint.com/index.php?m=cpcareers\u0026a=search)\n- [Cisco](https://www.cisco.com/) - [_Jobs_](https://jobs.cisco.com/jobs/SearchJobs/malware)\n- [Cisco Talos](https://blog.talosintelligence.com/) - [_Jobs_](https://talosintelligence.com/careers)\n- [Comodo](https://www.comodo.com/) - [_Jobs_](https://www.comodo.com/careers/)\n- [CrowdStrike](https://www.crowdstrike.com/) - [_Jobs_](https://crowdstrike.wd5.myworkdayjobs.com/en-GB/crowdstrikecareers)\n- [Cybereason](https://www.cybereason.com/) - [_Jobs_](https://www.cybereason.com/careers/all-jobs)\n- [Cynet](https://www.cynet.com/) - [_Jobs_](https://www.cynet.com/careers)\n- [Deep Instinct](https://www.deepinstinct.com/) - [_Jobs_](https://www.deepinstinct.com/careers#open-positions)\n- [Eset](https://www.eset.com/) - [_Jobs_](https://jobs.eset.com/en-US/ESET_External)\n- [F-Secure](https://www.f-secure.com/) - [_Jobs_](https://company.f-secure.com/en/careers#latest-jobs)\n- [Forcepoint](https://www.forcepoint.com/) - [_Jobs_](https://forcepoint.wd1.myworkdayjobs.com/external-careers)\n- [Fortinet](https://www.fortinet.com/) - [_Jobs_](https://www.fortinet.com/corporate/careers)\n- [GenDigital](https://www.gendigital.com/us/en/) - [_Jobs_](https://gen.wd1.myworkdayjobs.com/en-US/careers)\n- [Halcyon](https://www.halcyon.ai/) - [_Jobs_](https://www.halcyon.ai/careers)\n- [HP Wolf Security](https://www.hpwolf.com/) - [_Jobs_](https://jobs.hpwolf.com/)\n- [IBM](https://www.ibm.com/) - [_Jobs_](https://www.ibm.com/careers/search)\n- [Juniper Networks](https://www.juniper.net/) - [_Jobs_](https://jobs.juniper.net/)\n- [Malwarebytes](https://www.malwarebytes.com/) - [_Jobs_](https://www.malwarebytes.com/jobs?p=jobs%2Fviewall)\n- [McAfee](https://www.mcafee.com/) - [_Jobs_](https://careers.mcafee.com/global/en)\n- [Netskope](https://www.netskope.com/) - [_Jobs_](https://www.netskope.com/company/careers/open-positions)\n- [Nozomi Networks](https://www.nozominetworks.com/) - [_Jobs_](https://www.nozominetworks.com/company/careers#openings)\n- [Palo Alto Networks](https://www.paloaltonetworks.com/) - [_Jobs_](https://jobs.paloaltonetworks.com/en/)\n- [Qualys](https://www.qualys.com/) - [_Jobs_](https://www.qualys.com/careers)\n- [ReversingLabs](https://www.reversinglabs.com/) - [_Jobs_](https://www.reversinglabs.com/company/careers)\n- [SentinelOne](https://www.sentinelone.com/) - [_Jobs_](https://www.sentinelone.com/jobs/)\n- [Sophos](https://www.sophos.com/) - [_Jobs_](https://jobs.lever.co/sophos)\n- [Tanium](https://www.tanium.com/) - [_Jobs_](https://www.tanium.com/careers/#jobs)\n- [Tenable](https://www.tenable.com/) - [_Jobs_](https://www.tenable.com/careers/search)\n- [Thales](https://cpl.thalesgroup.com/) - [_Jobs_](https://careers.thalesgroup.com/)\n- [Trellix](https://www.trellix.com/) - [_Jobs_](https://careers.trellix.com/)\n- [Varonis](https://www.varonis.com/) - [_Jobs_](https://careers.varonis.com/)\n- [WatchGuard](https://www.watchguard.com/) - [_Jobs_](https://jobs.lever.co/watchguard)\n- [WithSecure](https://www.withsecure.com/) - [_Jobs_](https://www.withsecure.com/en/about-us/careers/open-positions/)\n- [Zscaler](https://www.zscaler.com/) - [_Jobs_](https://www.zscaler.com/careers/search)\n\n##\n\n### My Other Awesome Lists\nYou can access the my other awesome lists [here](https://cyberthreatdefence.com/my_awesome_lists)\n\n### Contributing\n\n[Contributions of any kind welcome, just follow the guidelines](contributing.md)!\n\n### Contributors\n[Thanks goes to these contributors](https://github.com/cybersecurity-dev/awesome-malware-reverse-engineering-certification/graphs/contributors)!\n\n### License\n[![CC0](http://mirrors.creativecommons.org/presskit/buttons/88x31/svg/cc-zero.svg)](http://creativecommons.org/publicdomain/zero/1.0)\n\n[🔼 Back to top](#awesome-malware--reverse-engineering-certification-)\n","projects_url":"https://awesome.ecosyste.ms/api/v1/lists/cybersecurity-dev%2Fawesome-malware-reverse-engineering-certification/projects"}